feat(standards): add TAP lifetime and length configuration - #126
Open
jspern wants to merge 1 commit into
Open
Conversation
Expose minimum, maximum, and default TAP lifetime along with TAP length as configurable options on the Enable Temporary Access Passes standard. Previously only the single-use/multi-logon toggle was exposed, and the lifetime and length values silently fell back to the Set-CIPPAuthenticationPolicy parameter defaults. Validate the configuration before contacting Graph: the run is skipped with an error when the minimum lifetime exceeds the maximum, or when the default lifetime falls outside that range, rather than issuing a PATCH that Graph would reject. Absolute bounds are surfaced in the form via field validators. Drift detection, remediation, and the standards comparison report now cover all five settings. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Contributor
|
wondering two things, haven't audited full code path yet: 1.) Is it backwards compatible and will it not alert on drift for people that have not modified their standard 2.) should we introduce this, or recommend the complete auth settings standard instead? |
Contributor
Author
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
add TAP lifetime and length configuration
Expose minimum, maximum, and default TAP lifetime along with TAP length as configurable options on the Enable Temporary Access Passes standard.
Previously only the single-use/multi-logon toggle was exposed, and the lifetime and length values silently fell back to the Set-CIPPAuthenticationPolicy parameter defaults.
Validate the configuration before contacting Graph: the run is skipped with an error when the minimum lifetime exceeds the maximum, or when the default lifetime falls outside that range, rather than issuing a PATCH that Graph would reject. Absolute bounds are surfaced in the form via field validators.
Drift detection, remediation, and the standards comparison report now cover all five settings.